Q

How can I redirect the event viewer files?

An admin is implementing a customer solution where each client PC loads an image from an image server on each boot-up. Since all the event viewer and log files are lost when the operating system reloads, he cannot perform forensic troubleshooting. He is wondering if there is a way to redirect the event viewer files to another partition or network share.

We are about to implement a client solution wherein each client PC loads an image from an image server on each boot-up. Since all the event viewer and log files are lost when the operating system reloads, we are unable to perform forensic troubleshooting. Is there a way to redirect the event viewer files to another partition or network share?
Microsoft's Audit Collection Service (ACS) has been in beta for quite some time now, so your current best bets would be either to create a scheduled job on each workstation that dumps the system logs and copies them to a central location, or else to use a third-party utility for Event Log collection such as DorianSoft's Event Archiver: ( http://www.doriansoft.com/totalsolution/).

When deciding on a solution, remember that Event Log data is critical information that should not be transmitted or stored in an insecure fashion; be sure that the security of your log data both in transit and in storage is a key factor in your decision-making process.

This was first published in November 2005

Dig deeper on Windows Server and Network Security

Pro+

Features

Enjoy the benefits of Pro+ membership, learn more and join.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

0 comments

Oldest 

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

-ADS BY GOOGLE

SearchServerVirtualization

SearchCloudComputing

SearchExchange

SearchSQLServer

SearchWinIT

SearchEnterpriseDesktop

SearchVirtualDesktop

Close